Project Galileo’s eighth year: Attack data from Ukraine and beyond

Cloudflare’s Project Galileo provides free cyber protection to vulnerable organizations — journalists, human rights defenders, and community groups — and its eighth-anniversary report analyzes attack data from July 1, 2021 through May 5, 2022. The findings cover nearly 1,900 participating organizations globally and reveal how the war in Ukraine reshaped threat patterns for these groups.

Researchers and targeted organizations can use the full dashboard to explore attack trends by region and sector. This analysis focuses on DDoS and web application firewall (WAF) mitigations, which reflect attempts to knock sites offline or exploit application vulnerabilities.

The scale of attacks in numbers

Over the nine-month period, Project Galileo participants faced nearly 18 billion cyberattacks — an average of roughly 57.9 million per day, up almost 10% year over year. Key findings include:

  • Mitigated DDoS traffic targeting Ukrainian organizations peaked at 90% of total traffic during a significant attack on April 19.
  • Applications to Project Galileo jumped 177% in March 2022 following the start of the war in Ukraine.
  • Journalism and media organizations in Europe and the Americas saw traffic grow around 150% over the reporting period.
  • European organizations consistently accounted for half to two-thirds of all request traffic across covered regions.
  • HTTP anomalies triggered the most WAF blocks, associated with up to 40% of mitigated requests for human rights and journalism organizations.
BLOG-1199 Embedded Image - 30xRIX

Ukraine: Attacks ramp up after the invasion

Before the war, traffic from Ukrainian organizations under Project Galileo was largely flat. After the invasion began, growth was driven mainly by journalism and media outlets, alongside community and social welfare groups providing aid to refugees.

Ukrainian human rights and journalism organizations experienced distinct attack patterns. Ahead of the conflict, WAF-mitigated traffic mostly affected community and social welfare sites. After the war started, journalism organizations saw the most WAF-mitigated traffic, with a notable spike on March 13 that accounted for 69% of their traffic. During the late-February surge, most attacks were classified as SQL injection attempts, while human rights organizations saw WAF mitigations rise to 5–10% of their traffic by mid-March.

BLOG-1199 Embedded Image - aZ1FVD

DDoS traffic against Ukrainian groups concentrated between mid-March and May. Early spikes hovered around 20% of traffic, but the April 19 attack overwhelmed legitimate requests, with mitigation covering more than 90% of that day’s traffic.

BLOG-1199 Embedded Image - vAcadG

Post-war traffic growth varied by sector:

  • Health organizations in Ukraine saw traffic increase 20–30x over baseline between late March and late April.
  • Journalism organizations sustained increases of 3–4x over baseline, excluding attack spikes.
  • Other organizational categories generally stayed below 3x baseline growth.
BLOG-1199 Embedded Image - D7Rgpl

Attack methods across regions and sectors

Looking at all regions — the Americas, Asia Pacific, Europe, and Africa/Middle East — HTTP anomalies were the most common WAF trigger, accounting for 28% of mitigated requests. SQL injection attempts represented 20%, and exploits of specific CVEs nearly 13%. These trends align with the previous year’s report, which similarly highlighted SQLi and user agent anomalies as dominant mitigation triggers.

BLOG-1199 Embedded Image - 5IfNID

HTTP anomalies are requests that break from expected web request structure — malformed headers, unsupported methods, non-standard ports, or invalid character encoding. These are often unsophisticated attack attempts but can still damage unprotected sites, so Cloudflare’s WAF blocks them automatically. For human rights and journalism organizations, this rule type accounted for up to 40% of WAF blocks, the largest share of any rule category.

SQLi remains a core threat: attackers inject malicious SQL statements into form fields to retrieve, modify, or destroy database contents. Across all protected organizations, most WAF-mitigated traffic fell into either the HTTP anomaly or SQLi category.

BLOG-1199 Embedded Image - EsqkBF

Organizations already under attack in Ukraine can apply for expedited protection under Project Galileo at www.cloudflare.com/galileo, and Cloudflare says it continues onboarding groups in Ukraine and neighboring countries to maintain access to independent information.